CWE-668
Exposure of Resource to Wrong Sphere
Description
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.
Hierarchy (View 1000)
CVEs mapped to this weakness (784)
page 36 of 40| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-29820 | Low | 0.20 | 3.0 | 0.00 | Apr 28, 2022 | In JetBrains PyCharm before 2022.1 exposure of the debugger port to the internal network was possible | ||
| CVE-2026-34094 | Low | 0.18 | 3.8 | 0.00 | May 11, 2026 | Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Page/Article.Php. This issue affects MediaWiki: from * before 1.43.7, 1.44.4, 1.45.2. | ||
| CVE-2023-2622 | Low | 0.18 | 2.7 | 0.00 | Nov 1, 2023 | Authenticated clients can read arbitrary files on the MAIN Computer system using the remote procedure call (RPC) of the InspectSetup service endpoint. The low privilege client is then allowed to read arbitrary files that they do not have authorization to read. | ||
| CVE-2023-29192 | Low | 0.18 | 2.7 | 0.00 | Apr 10, 2023 | SilverwareGames.io versions before 1.2.19 allow users with access to the game upload panel to edit download links for games uploaded by other developers. This has been fixed in version 1.2.19. | ||
| CVE-2023-27265 | Low | 0.18 | 2.7 | 0.01 | Feb 27, 2023 | Mattermost fails to honor the ShowEmailAddress setting when constructing a response to the "Regenerate Invite Id" API endpoint, allowing an attacker with team admin privileges to learn the team owner's email address in the response. | ||
| CVE-2022-34452 | Low | 0.18 | 2.7 | 0.00 | Feb 10, 2023 | PowerPath Management Appliance with versions 3.3, 3.2*, 3.1 & 3.0* contains sensitive information disclosure vulnerability. An Authenticated admin user can able to exploit the issue and view sensitive information stored in the logs. | ||
| CVE-2026-32690 | Low | 0.17 | 3.7 | 0.00 | Apr 18, 2026 | Secrets in Variables saved as JSON dictionaries were not properly redacted - in case thee variables were retrieved by the user the secrets stored as nested fields were not masked. If you do not store variables with sensitive values in JSON form, you are not affected. Otherwise… | ||
| CVE-2023-29203 | Low | 0.17 | 3.7 | 0.01 | Apr 15, 2023 | XWiki Commons are technical libraries common to several other top level XWiki projects. It's possible to list some users who are normally not viewable from subwiki by requesting users on a subwiki which allows only global users with `uorgsuggest.vm`. This issue only concerns… | ||
| CVE-2023-32394 | Low | 0.16 | 2.4 | 0.00 | Jun 23, 2023 | The issue was addressed with improved checks. This issue is fixed in iOS 16.5 and iPadOS 16.5, watchOS 9.5, tvOS 16.5, macOS Ventura 13.4. A person with physical access to a device may be able to view contact information from the lock screen. | ||
| CVE-2025-68467 | Low | 0.15 | 3.4 | 0.00 | Mar 4, 2026 | Dark Reader is an accessibility browser extension that makes web pages colors dark. The dynamic dark mode feature of the extension works by analyzing the colors of web pages found in CSS style sheet files. In order to analyze cross-origin style sheets (stored on websites… | ||
| CVE-2023-35013 | Low | 0.15 | 2.3 | 0.00 | Oct 16, 2023 | IBM Security Verify Governance 10.0, Identity Manager could allow a local privileged user to obtain sensitive information from source code. IBM X-Force ID: 257769. | ||
| CVE-2026-6830 | Low | 0.14 | 3.3 | 0.00 | Apr 21, 2026 | nesquena hermes-webui contains an environment variable leakage vulnerability where profile switching does not clear environment variables from the previously active profile before loading the next profile. Attackers or users can exploit additive dotenv reload behavior to access… | ||
| CVE-2023-5545 | Low | 0.14 | 3.3 | 0.01 | Nov 9, 2023 | H5P metadata automatically populated the author with the user's username, which could be sensitive information. | ||
| CVE-2023-5542 | Low | 0.14 | 3.3 | 0.00 | Nov 9, 2023 | Students in "Only see own membership" groups could see other students in the group, which should be hidden. | ||
| CVE-2023-0481 | Low | 0.14 | 3.3 | 0.00 | Feb 24, 2023 | In RestEasy Reactive implementation of Quarkus the insecure File.createTempFile() is used in the FileBodyHandler class which creates temp files with insecure permissions that could be read by a local user. | ||
| CVE-2023-21438 | Low | 0.14 | 2.1 | 0.00 | Feb 9, 2023 | Improper logic in HomeScreen prior to SMR Feb-2023 Release 1 allows physical attacker to access App preview protected by Secure Folder. | ||
| CVE-2022-41954 | Low | 0.14 | 3.3 | 0.00 | Nov 25, 2022 | MPXJ is an open source library to read and write project plans from a variety of file formats and databases. On Unix-like operating systems (not Windows or macos), MPXJ's use of `File.createTempFile(..)` results in temporary files being created with the permissions `-rw-r--r--`.… | ||
| CVE-2022-29247 | Low | 0.14 | 2.2 | 0.01 | Jun 13, 2022 | Electron is a framework for writing cross-platform desktop applications using JavaScript (JS), HTML, and CSS. A vulnerability in versions prior to 18.0.0-beta.6, 17.2.0, 16.2.6, and 15.5.5 allows a renderer with JS execution to obtain access to a new renderer process with… | ||
| CVE-2022-28794 | Low | 0.14 | 2.2 | 0.00 | Jun 7, 2022 | Sensitive information exposure in low-battery dumpstate log prior to SMR Jun-2022 Release 1 allows local attackers to get SIM card information. | ||
| CVE-2017-8418 | Low | 0.14 | 3.3 | 0.00 | May 2, 2017 | RuboCop 0.48.1 and earlier does not use /tmp in safe way, allowing local users to exploit this to tamper with cache files belonging to other users. |
- risk 0.20cvss 3.0epss 0.00
In JetBrains PyCharm before 2022.1 exposure of the debugger port to the internal network was possible
- risk 0.18cvss 3.8epss 0.00
Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Page/Article.Php. This issue affects MediaWiki: from * before 1.43.7, 1.44.4, 1.45.2.
- risk 0.18cvss 2.7epss 0.00
Authenticated clients can read arbitrary files on the MAIN Computer system using the remote procedure call (RPC) of the InspectSetup service endpoint. The low privilege client is then allowed to read arbitrary files that they do not have authorization to read.
- risk 0.18cvss 2.7epss 0.00
SilverwareGames.io versions before 1.2.19 allow users with access to the game upload panel to edit download links for games uploaded by other developers. This has been fixed in version 1.2.19.
- risk 0.18cvss 2.7epss 0.01
Mattermost fails to honor the ShowEmailAddress setting when constructing a response to the "Regenerate Invite Id" API endpoint, allowing an attacker with team admin privileges to learn the team owner's email address in the response.
- risk 0.18cvss 2.7epss 0.00
PowerPath Management Appliance with versions 3.3, 3.2*, 3.1 & 3.0* contains sensitive information disclosure vulnerability. An Authenticated admin user can able to exploit the issue and view sensitive information stored in the logs.
- risk 0.17cvss 3.7epss 0.00
Secrets in Variables saved as JSON dictionaries were not properly redacted - in case thee variables were retrieved by the user the secrets stored as nested fields were not masked. If you do not store variables with sensitive values in JSON form, you are not affected. Otherwise…
- risk 0.17cvss 3.7epss 0.01
XWiki Commons are technical libraries common to several other top level XWiki projects. It's possible to list some users who are normally not viewable from subwiki by requesting users on a subwiki which allows only global users with `uorgsuggest.vm`. This issue only concerns…
- risk 0.16cvss 2.4epss 0.00
The issue was addressed with improved checks. This issue is fixed in iOS 16.5 and iPadOS 16.5, watchOS 9.5, tvOS 16.5, macOS Ventura 13.4. A person with physical access to a device may be able to view contact information from the lock screen.
- risk 0.15cvss 3.4epss 0.00
Dark Reader is an accessibility browser extension that makes web pages colors dark. The dynamic dark mode feature of the extension works by analyzing the colors of web pages found in CSS style sheet files. In order to analyze cross-origin style sheets (stored on websites…
- risk 0.15cvss 2.3epss 0.00
IBM Security Verify Governance 10.0, Identity Manager could allow a local privileged user to obtain sensitive information from source code. IBM X-Force ID: 257769.
- risk 0.14cvss 3.3epss 0.00
nesquena hermes-webui contains an environment variable leakage vulnerability where profile switching does not clear environment variables from the previously active profile before loading the next profile. Attackers or users can exploit additive dotenv reload behavior to access…
- risk 0.14cvss 3.3epss 0.01
H5P metadata automatically populated the author with the user's username, which could be sensitive information.
- risk 0.14cvss 3.3epss 0.00
Students in "Only see own membership" groups could see other students in the group, which should be hidden.
- risk 0.14cvss 3.3epss 0.00
In RestEasy Reactive implementation of Quarkus the insecure File.createTempFile() is used in the FileBodyHandler class which creates temp files with insecure permissions that could be read by a local user.
- risk 0.14cvss 2.1epss 0.00
Improper logic in HomeScreen prior to SMR Feb-2023 Release 1 allows physical attacker to access App preview protected by Secure Folder.
- risk 0.14cvss 3.3epss 0.00
MPXJ is an open source library to read and write project plans from a variety of file formats and databases. On Unix-like operating systems (not Windows or macos), MPXJ's use of `File.createTempFile(..)` results in temporary files being created with the permissions `-rw-r--r--`.…
- risk 0.14cvss 2.2epss 0.01
Electron is a framework for writing cross-platform desktop applications using JavaScript (JS), HTML, and CSS. A vulnerability in versions prior to 18.0.0-beta.6, 17.2.0, 16.2.6, and 15.5.5 allows a renderer with JS execution to obtain access to a new renderer process with…
- risk 0.14cvss 2.2epss 0.00
Sensitive information exposure in low-battery dumpstate log prior to SMR Jun-2022 Release 1 allows local attackers to get SIM card information.
- risk 0.14cvss 3.3epss 0.00
RuboCop 0.48.1 and earlier does not use /tmp in safe way, allowing local users to exploit this to tamper with cache files belonging to other users.